Olvano
  • Features
  • Pricing
  • Tools
  • Docs
  • Blog
  • Changelog
Sign in

Privacy Policy

How Olvano processes and protects personal data in compliance with the GDPR.

Version 1.0 · effective from 29 June 2026

This Policy describes how the Olvano service (https://olvano.cz) processes and protects personal data in compliance with Regulation (EU) 2016/679 (GDPR) and zákonem č. 110/2019 Sb., on personal data processing.


1. Data controller

Daniel Krůl registered office: Mlýnská 1692/7, Moravská Ostrava, 702 00 Ostrava IČO: 09161244, registered in the Trade Licensing Register e-mail: dankrul.krul@gmail.com (the "Operator" or "Controller").

The Operator has not appointed a data protection officer; in matters of personal data protection, the Operator can be contacted at the e-mail address stated above.

2. The Operator's dual role: controller vs. processor

This is a key distinction for Olvano:

2.1 The Operator is the controller of the personal data that it itself determines and processes – i.e. the data of users of the Service (registration, subscription), website visitors, senders of the contact form and newsletter subscribers. This processing is subject to this Policy.

2.2 The Operator is the processor of the personal data that the user enters into the Service about third parties (in particular about their clients and business partners, invoice recipients and persons signing documents). For this data, the user is the controller, and the Operator processes it solely on the user's behalf and according to the user's instructions on the basis of the Data Processing Agreement (DPA) concluded pursuant to čl. 28 GDPR. This Policy does not further govern such processing – it is governed by the said DPA.

3. What data we process, for what purpose and on what legal basis

As a controller, we process:

a) The user's registration and accounting data (first name, surname / company name, e-mail, login credentials, the entrepreneur's identification and billing data).

  • Purpose: setting up and maintaining the account, providing the Service, communication.
  • Legal basis: performance of a contract – čl. 6 odst. 1 písm. b) GDPR.

b) Subscription payment data (data about the order and about the payment received by bank transfer, in particular the variable symbol and the amount paid).

  • Purpose: processing payments, issuing tax documents, bookkeeping.
  • Legal basis: performance of a contract – čl. 6 odst. 1 písm. b) and compliance with a legal obligation (accounting and tax regulations) – čl. 6 odst. 1 písm. c) GDPR.

c) Technical and operational data (IP address, logs, device identifiers, data about the use of the Service).

  • Purpose: security, prevention of misuse, operation and improvement of the Service, diagnostics.
  • Legal basis: legitimate interest – čl. 6 odst. 1 písm. f) GDPR.

d) Analytical data (Google Analytics) by means of cookies.

  • Purpose: measuring traffic and improving the website.
  • Legal basis: consent – čl. 6 odst. 1 písm. a) GDPR (given in the cookie banner); it can be withdrawn at any time.

e) Contact form data (name, e-mail, content of the message).

  • Purpose: handling the inquiry.
  • Legal basis: legitimate interest, or negotiation of a contract – čl. 6 odst. 1 písm. f) or b) GDPR.

f) Newsletter subscribers' data (e-mail).

  • Purpose: sending news and commercial communications.
  • Legal basis: consent – čl. 6 odst. 1 písm. a) GDPR, or legitimate interest for the Operator's own customers under § 7 zákona č. 480/2004 Sb. The subscription can be cancelled at any time.

4. Retention period

4.1 We process the user's data for the duration of the account and thereafter for the period necessary to protect the Operator's rights.

4.2 We retain accounting and tax documents for the period stipulated by law (typically 10 years, or pursuant to the Accounting Act and the Value Added Tax Act).

4.3 We process data processed on the basis of consent until the consent is withdrawn. We retain logs and technical data for a reasonable period necessary for the given purpose.

5. Recipients and processors

5.1 Personal data may be made available to our processors who ensure the operation of the Service for us. As of the effective date of this Policy, these are in particular:

Category Provider Location
Hosting / cloud infrastructure Google Cloud (Firebase App Hosting) EU/EEA
Database Railway EU/EEA
Sending e-mails (transactional / invoicing) Twilio SendGrid EU/EEA
Contract signature verification via SMS Twilio EU/EEA
Web analytics Google Analytics 4 (Google Ireland Ltd.) EU + USA

5.2 We may pass data on to public authorities if required by legal regulations.

6. Transfer outside the EU/EEA

6.1 Data is primarily processed on servers in the European Union. If a transfer to a third country occurs with any processor (e.g. Google Analytics), this transfer is secured by appropriate safeguards under čl. 46 GDPR (in particular the European Commission's standard contractual clauses), or on the basis of an adequacy decision (EU–US Data Privacy Framework).

7. Rights of data subjects

7.1 In connection with the processing, you have the right to: access to your data, rectification, erasure ("the right to be forgotten"), restriction of processing, portability of your data, objection to processing based on legitimate interest, and withdrawal of consent (where the processing is based on consent).

7.2 You may exercise your rights at the e-mail dankrul.krul@gmail.com. We will handle them without undue delay, at the latest within one month.

7.3 You also have the right to lodge a complaint with the supervisory authority, which is the Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz.

8. Cookies

8.1 The website uses necessary cookies required for the functioning of the website (legal basis: legitimate interest) and analytical cookies (Google Analytics), which we deploy only with your consent given in the cookie banner (§ 89 odst. 3 zákona č. 127/2005 Sb., on electronic communications).

8.2 The consent settings can be changed at any time via the "Cookie settings" link on the website.

9. Security

The Operator has adopted appropriate technical and organizational measures to secure personal data, in particular storing data on servers in the EU, restricting access to authorized persons only, and encryption of transmission. However, no measure provides an absolute guarantee of security.

10. Changes to the Policy

This Policy may be updated. We will inform you of material changes on the website or by e-mail. The current version is always available at https://olvano.cz/privacy.

Product

  • Features
  • Pricing
  • Changelog
  • Olvano NIS2

Resources

  • Tools
  • Docs
  • Blog
  • API reference

Company

  • Contact
  • Sign in
  • Sign up

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement (DPA)

© 2026 Olvano — All rights reserved.

Operator: Daniel Krůl, Mlýnská 1692/7, Moravská Ostrava, 702 00 Ostrava · IČO: 09161244

Sole trader registered in the Czech Trade Licensing Register.

Made with by Daniel Krůl

We value your privacy

With your consent we use analytics cookies (Google Analytics) to understand traffic and improve the site. Learn more in our privacy policy